Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8419667
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 10, 20262026-06-10T02:40:36+00:00 2026-06-10T02:40:36+00:00

I am using HOTP to generate OTP for second factor authentication. I am using

  • 0

I am using HOTP to generate OTP for second factor authentication. I am using event-based generation of OTP and providing a window of 10 iterations should there be mismatch in the counter of client and server.

However, I am being asked that what happens if an OTP is re-generated from past at any point of time.

Since the OTP is a 6 digit number, there could be only 999999 combinations available for a user. Hence, an OTP cannot be unique in the lifetime and it will be regenerated at some point. Could there be a pattern when a particular OTP repeats?

Also, if an OTP is regenerated within a window size of 10, it could be worse as it would be vulnerable to replay attack.

Kindly guide me on this.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-10T02:40:37+00:00Added an answer on June 10, 2026 at 2:40 am

    No, there should not be a repeating predictable pattern if you don’t know the secret key by using randomness (it would be an important discovery and flaw in the algorithm to be otherwise).

    Although you can tolerate a windows size of 10, only tolerate that going forward. Never accept a token that is less than the last confirmed counter, otherwise you are leaving open a replay attack.

    HOTP, TOTP or anything else isn’t immune to all forms of attack, of course, so you need a multi-layered approach to your security that is realistic about the vectors of attack vs. the cost of defending.

    A more in depth discussion is probably best had here. In this answer I’m trying to stick the implementation issues.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

mod_authn_otp is an Apache web server module for two-factor authentication using one-time passwords (OTP)
Using Microsoft SQL Server 2005, is there any way to see when a table
I'm working on a one-time password application, using the hotp algorithm (RFC 4226). I've
Using android 2.3.3, I have a background Service which has a socket connection. There's
I am trying to implement a OTP solution in C# based on RFC 4226:
Using Xcode4.2.1, with a basic PhoneGap template based app. (I say template, but I
Using jQuery UI Resizable I'm trying to prevent resizing based on various rules. The
Using ASP.NET MVC there are situations (such as form submission) that may require a
Using TortoiseSVN against VisualSVN I delete a source file that I should not have
Using C# and System.Data.SqlClient, is there a way to retrieve a list of parameters

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.